Email Spoofing Explained: Why Emails From Trusted Names Can't Always Be Trusted

Key Takeaways
Email spoofing is when attackers forge the sender address on an email so it appears to come from a trusted source. Because the email protocol SMTP has no built-in sender verification, spoofed emails can pass security filters and fool recipients into clicking malicious links, handing over credentials, or transferring money.
You get an email from your bank. The name looks right, the logo looks right, and the message sounds urgent. You click the link.
What you didn't know is that email never came from your bank at all.
That's email spoofing: a technique where attackers forge the sender's identity to make a message look like it came from someone you trust. It's one of the oldest tricks in the book, and it still works because it exploits something fundamental about how email was built.
What is email spoofing?
Email spoofing is when someone forges the sender address on an email so it appears to come from a trusted source. The email looks legitimate on the surface, but the actual sender has nothing to do with the name or domain displayed. It's identity fraud, applied to your inbox.
The technique has been around since the early days of email. It works because the core protocol emails run on, called SMTP (Simple Mail Transfer Protocol), was built for reliability, not security. It has no built-in way to verify that the person sending an email is actually who they say they are. Attackers have exploited this gap for decades.
The visible result is an email that shows a real company's name and a real-looking address, sent from infrastructure that company has never touched. Your inbox has no obvious way to tell you the difference.
How does email spoofing work?
Every email has two layers: what you see and what's happening underneath.
What you see is the display name, the sender address, and the message body. What's happening underneath is the SMTP envelope, the technical information servers use to actually route and deliver the email. The key thing to understand is these two layers don't have to match.
Attackers exploit this by editing the visible 'From' header field to show any name and email address they choose, while the actual sending infrastructure is something entirely different. As Cloudflare explains, because 'the SMTP envelope never checks the header and the recipient cannot see the information in the envelope, email spoofing is relatively easy.'
The result: your inbox shows an email from support@yourbank.com, but the actual origin is a mail server somewhere else entirely.
Spoofing can also take more subtle forms:
- Display name spoofing: The visible name matches a real person or brand, but the actual email address behind it is different. You might see 'PayPal Support' with an address like paypal-support@gmail.com.
- Domain impersonation: A fake domain that looks almost right, like paypa1.com instead of paypal.com.
- Lookalike addresses: A real-looking email that uses a trusted name misleadingly, like ceo.john@examplecompany.support.
Why spoofed emails can pass security checks
Here's where it gets uncomfortable. A spoofed email can sometimes clear every security filter your inbox uses and still land looking completely legitimate.
Most people assume that if an email passes spam filters, it's safe. But the filters themselves can be fooled. Modern email security relies on a set of authentication protocols: SPF (Sender Policy Framework), DKIM (DomainKeys Identified Mail), and DMARC (Domain-based Message Authentication, Reporting, and Conformance). These exist to verify that emails come from authorized servers. When configured correctly, they work well. When misconfigured, or when attackers find a way around them, they become part of the problem.
Guardio Labs discovered exactly this kind of exploit in 2024. The campaign, dubbed EchoSpoofing, exploited a misconfiguration in Proofpoint's email protection infrastructure. Attackers sent millions of emails that appeared to come from real brands like Disney, Nike, IBM, and Coca-Cola, complete with valid SPF and DKIM authentication signatures. Gmail received these emails and fully authenticated them. They looked, by every technical measure, like they came from those companies.
This wasn't a flaw in the brands themselves. It was a flaw in the trusted relay infrastructure sitting between brands and their customers. The emails literally echoed out from Proofpoint's own servers, which is exactly how the campaign got its name.
Authentication protocols are only as strong as their configuration.
What do spoofed emails actually want from you?
Spoofed emails are rarely random. They're built around a specific goal, and that goal is almost always to get something from you.
The most common objectives:
- Steal credentials. A spoofed email from your bank, email provider, or HR system asks you to log in via a link. The page looks real. Your username and password go straight to the attacker.
- Get money transferred. Business Email Compromise (BEC) is a form of email fraud where attackers impersonate executives or vendors to redirect payments. According to the FBI's IC3 2024 Annual Report, BEC generated nearly $2.8 billion in losses in 2024 alone, and close to $8.5 billion across the last three years combined.
- Install malware. An attachment that looks like an invoice or a shipping notice installs malicious software when opened.
- Harvest personal information. A fake notice asks you to confirm your details 'for security purposes.' Once you do, those details are in the wrong hands.
Phishing and spoofing were the single most reported crime category to the FBI in 2024, with 193,407 complaints filed to IC3. These aren't edge cases.
How to spot a spoofed email
Spoofed emails are built to look convincing, but there are things you can check.
Look past the display name. The name shown in your inbox might say 'Chase Bank' or 'Microsoft Support,' but hover over it or tap to expand the actual sending address. If it doesn't match the official domain exactly, that's a red flag.
Watch for urgency and pressure. 'Your account will be suspended in 24 hours.' 'Immediate action required.' These phrases are meant to short-circuit your judgment. Real organizations rarely demand instant action via email without any prior contact.
Check the reply-to address. Sometimes the 'From' field looks right, but the reply-to is completely different. If you reply, your response goes to the attacker, not the organization.
Inspect the email header. In Gmail, click the three-dot menu on an email and select 'Show original.' Look for the 'Received' field and compare the actual sending domain to what's shown in the 'From' line. A mismatch means the email didn't come from where it claims.
Treat unexpected requests as suspicious. If an email asks you to log in, transfer money, or confirm personal details and you weren't expecting it, don't act on it. Call the organization directly using a number from their official website.
How to protect yourself from email spoofing
Awareness alone isn't enough. Here's what actually reduces your risk.
Use a security tool that works at the browser level, on your computer and your phone. Spoofed emails often lead to fake websites where the real damage happens. Guardio detects and blocks those destinations before you land on them, even when the email that sent you there looked completely real.
Turn on two-factor authentication (2FA). Even if an attacker gets your credentials through a spoofed email, 2FA means they can't access your account without a second verification step. Apply this to your email, banking, and any accounts that store sensitive information.
Don't click links in emails that ask for account access. Open a new browser tab and navigate directly to the site instead. Type the address yourself or use a saved bookmark you already trust.
Keep your email client updated. Providers like Gmail and Outlook regularly improve their spoofing detection. You benefit automatically when those updates are running.
Report suspicious emails. Most email clients have a 'Report phishing' option. Using it helps train filters for everyone. You can also forward suspicious emails to the security team of the company being impersonated.
Spoofed emails are increasingly polished. They get past filters, pass authentication checks, and use real brand assets. The combination of a skeptical eye and a security layer that fills in the gaps is what keeps you protected.
Conclusion
Email spoofing works because it exploits a gap that's been in the email system since the beginning. The protocol wasn't built with trust verification in mind, and attackers have had decades to get good at using that gap.
Knowing how it works is the first step. Checking sender addresses, treating urgency as a warning sign, and having a security layer that catches the threats your inbox misses, those are the habits that actually make a difference.
You don't need to be a security expert to stay protected. You just need the right habits and the right tools. Get started with a free scan today
FAQs
What is email spoofing?
Email spoofing is when an attacker forges the sender address on an email to make it appear as if it came from a trusted source, like a bank, a well-known brand, or a colleague. Because the email protocol SMTP has no built-in sender verification, attackers can edit the visible 'From' field without any access to the real organization's systems. The goal is typically to steal credentials, redirect payments, or install malware.
How does email spoofing work technically?
Email spoofing works by exploiting a mismatch between two layers of every email: the visible header (what you see) and the SMTP envelope (what servers use to deliver it). Attackers edit the 'From' header to show any name or address they choose, while the actual sending infrastructure is completely different. Because email servers don't require these two layers to match, a spoofed message can be sent without access to the impersonated domain.
Can a spoofed email pass spam filters?
Yes, spoofed emails can pass spam and authentication filters. Modern email security uses SPF, DKIM, and DMARC protocols to verify senders, but these only work when correctly configured. In 2024, Guardio Labs uncovered EchoSpoofing, a campaign where attackers sent millions of emails impersonating Disney, Nike, IBM, and others with fully valid SPF and DKIM signatures, all authenticated by Gmail. Misconfigured infrastructure made it possible.
How can I tell if an email is spoofed?
Check the actual email address behind the display name, not just the name itself. In Gmail, click 'Show original' to view the full email header and compare the 'Received' domain to the 'From' address. A mismatch means the email didn't originate where it claims. Also watch for mismatched reply-to addresses, urgent language, and unexpected requests to log in or confirm personal details.
Is email spoofing illegal?
Email spoofing used to deceive people or commit fraud is illegal in the United States under the CAN-SPAM Act and other federal statutes. When spoofing is used as part of phishing, Business Email Compromise (BEC), or identity theft schemes, it can also trigger charges under the Computer Fraud and Abuse Act. The FBI's IC3 recorded 193,407 phishing and spoofing complaints in 2024 alone.
What is the difference between email spoofing and phishing?
Email spoofing is a technique, specifically forging the sender's identity on an email. Phishing is an attack type that uses deception to steal information or money. Spoofing is one of the main tools used to make phishing emails more convincing, because an email that appears to come from your bank is far more likely to trick you than one from an unknown address. The two terms are related but not interchangeable.
How can I protect myself from spoofed emails?
Protect yourself by enabling two-factor authentication (2FA) on important accounts so stolen credentials can't be used alone, avoiding clicking links in unsolicited emails requesting account access, and using a browser-level security tool like Guardio that works on both your computer and your phone that detects and blocks malicious destinations even when the email that sent you there looked legitimate. Reporting suspicious emails also helps providers improve detection for everyone.




%201.avif)

